When the IPS-enabled engine detects a certain number of failed network connections to or from the same IP address occurring within a rolling 60‑second window, a reconnaissance attack is suspected. Based on this and other criteria, the engine determines whether the suspicious activity constitutes a reconnaissance event.
The system initializes with default threshold values for ping sweep detection and port scan detection. You can configure higher thresholds to reduce false positive IPS events.
Prerequisites
Log in to the IPS appliance as Operator or Admin.
Enable IPS detection of reconnaissance activity. See Enabling IPS detection of reconnaissance activity (CLI).
Procedure
Enable the CLI configuration mode.
hostname > enable hostname # configure terminal
Check the current status of the feature. In the following example, the feature is enabled with default values.
hostname (config) # show ips reconnaissance Ping sweep threshold : 20 Port scan threshold : 200 Brute force threshold : 5Configure a new ping sweep threshold value. In the following example, the threshold is raised to 35.
hostname (config) # ips ping-sweep threshold 35Configure a new port scan threshold value. In the following example, the threshold is raised to 300.
hostname (config) # ips port-scan threshold 300Confirm your changes.
hostname (config) # show ips reconnaissance Ping sweep threshold : 35 Port scan threshold : 300 Brute force threshold : 5Save your changes.
hostname (config) # write memory